Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Local Priviledge escalation in Perfetto Dev scripts
Vulnerability Description
A local attacker, as a different local user, may be able to send a HTTP request to 127.0.0.1:10000 after the user (typically a developer) manually invoked the ./tools/run-dev-server script. It is recommended to upgrade to any version beyond 24.2
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Vulnerability Type
Permission Issues
Vulnerability Title
Google perfetto 安全漏洞
Vulnerability Description
Google perfetto是美国谷歌(Google)公司的用于通过 Android 调试桥 (ADB) 在 Android 设备上收集性能信息。 Google perfetto 存在安全漏洞,该漏洞源于用户(通常是开发人员)手动调用./tools/run-dev-server脚本后,可以向127.0.0.1:10000发送 HTTP 请求。建议升级到24.2以后的任何版本。
CVSS Information
N/A
Vulnerability Type
N/A